57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-15266 | MED 4.4 | cisco wireless_lan_controller_software A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line pa | 0.7% | — |
| CVE-2019-12620 | MED 5.3 | cisco hyperflex_hx220c_af_m5_firmware A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collec | 0.7% | — |
| CVE-2014-4027 | LOW 2.3 | canonical ubuntu_linux The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access t | 0.7% | — |
| CVE-2010-3689 | MED 6.9 | apache openoffice soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | 0.7% | — |
| CVE-2026-69550 | MED 6.5 | microsoft windows_app Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-65794 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-26136 | MED 6.5 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-53763 | CRIT 9.8 | microsoft purview_data_governance Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-38616 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux | 0.7% | — |
| CVE-2024-38163 | HIGH 7.8 | microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-45188 | MED 6.5 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this vulner | 0.7% | — |
| CVE-2021-40470 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40466 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40443 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-15936 | LOW 2.6 | fortinet fortios A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and below, version 5.6.13 and below allows attacker to disclose sensitive information via SNI Client Hello TLS packets. | 0.7% | — |
| CVE-2019-8912 | HIGH 7.8 | canonical ubuntu_linux In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr. | 0.7% | — |
| CVE-2026-66324 | MED 6.5 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2026-62913 | HIGH 8.8 | microsoft exchange_server Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-41107 | HIGH 7.4 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2024-47726 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait dio completion It should wait all existing dio write IOs before block removal, otherwise, previous direct write IO may overwrite data in the block which may be reused by ot | 0.7% | — |
| CVE-2024-43547 | MED 6.5 | microsoft windows_10_1507 Windows Kerberos Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-36913 | CRIT 9.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that a | 0.7% | — |
| CVE-2023-20877 | HIGH 8.8 | vmware cloud_foundation VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. | 0.7% | — |
| CVE-2023-20187 | HIGH 8.6 | cisco ios_xe A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a deni | 0.7% | — |
| CVE-2023-20086 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in ICMPv6 processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due t | 0.7% | — |